The PASSWORD History Count value must be set to 10 or greater.
An XCCDF Rule
Description
<VulnDiscussion>History Count specifies the number of previous passwords saved for each USERID and compares it with an intended new password. If there is a match with one of the previous passwords, or with the current password, it will reject the intended new password. The improper setting of any of these fields, individually or in combination with another, can compromise the security of the processing environment. </VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility>System Administrator</Responsibility><Responsibility>Information Assurance Officer</Responsibility><Responsibility>Information Assurance Manager</Responsibility><Responsibility>Systems Programmer</Responsibility><IAControls>IAIA-1, IAIA-2</IAControls>
- ID
- SV-30024r2_rule
- Severity
- Medium
- References
- Updated
Remediation - Manual Procedure
Have the System Administrator go into the Password Profile and set the History Count to 10 or greater.